Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

A company uses Amazon GuardDuty to monitor for malicious activity in their AWS account. The security team receives a GuardDuty finding that indicates an EC2 instance is communicating with a known cryptocurrency mining pool. The team needs to investigate the finding and determine which security group rules allowed the outbound traffic. The EC2 instance is in a VPC with a single security group attached. Which AWS service should the security team use to review the outbound traffic details?

⚠ Common exam trap

SCS-C02 often tests the distinction between CloudTrail (API activity) and VPC Flow Logs (network traffic) — candidates pick CloudTrail because it is the default 'audit' answer, but it cannot show packet-level outbound connections.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VPC Flow Logs

VPC Flow Logs capture IP traffic metadata — including source/destination IP, ports, protocol, and ACCEPT/REJECT action — for network interfaces in a VPC. Reviewing flow logs for the EC2 instance's ENI reveals which outbound traffic was allowed and, combined with the security group rules, identifies the rule that permitted the connection to the mining pool.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail records AWS API activity—actions like RunInstances, CreateSecurityGroup, and other control-plane calls—along with the source IP and user identity. It does not capture IP traffic statistics such as destination addresses, ports, packet counts, or byte totals for outbound connections. CloudTrail can reveal administrative changes that enable malicious behavior, but it cannot show the ongoing traffic flows that would indicate an instance is communicating with a known command-and-control server.

  • ✓

    VPC Flow Logs

    Why this is correct

    VPC Flow Logs capture metadata about every IP traffic flow accepted or rejected by a VPC network interface, including source/destination IP, source/destination port, protocol, packets, and bytes transferred. By enabling these logs for the subnets or ENIs and publishing to CloudWatch Logs or S3, you can query for outbound traffic to suspicious IP addresses, unusual ports, or high data transfer volumes. This raw flow-level data is exactly what is needed to supplement a GuardDuty finding and trace which EC2 instance initiated the malicious connection.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config evaluates recorded resource configuration states and changes against rules, tracking items such as security group rules, instance types, and tag compliance. It has no visibility into the actual network connections or flow records between instances and external hosts; it only knows how resources are configured. A Config rule might show that a security group allows broad egress, but it cannot identify whether a particular instance is actively sending traffic to a known malicious IP.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a managed threat-detection service that correlates findings from CloudTrail, VPC Flow Logs, and DNS logs to produce security alerts with severity and threat type. It does not expose the underlying raw traffic logs, and it does not preserve full flow metadata for the customer's own ad-hoc network investigation. GuardDuty tells you something suspicious happened, but to inspect the exact destination, port, and volume of outbound traffic you still need the raw VPC Flow Logs for that same time window.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.